Privacy Policy
Purpose
Nevada Health Link, Nevada’s Affordable Care Act (ACA) Administering Entity, will collect sensitive information from consumers in order to perform its ACA-mandated functions, such as enrollment in Qualified Health Plans (QHPs) or Standalone Dental Plans (SADPs) and eligibility for Advance Premium Tax Credits (APTC) and Cost Sharing Reductions (CSR). Personally-identifiable consumer information (PII) and Protected Health Information (PHI) are protected by federal law and state laws. This Privacy Policy describes how information about covered persons or Nevada Health Link consumers may be used, disclosed, and accessed.
Collection of Information
Nevada Health Link will only collect the minimum information required to achieve its mission of providing affordable health insurance to individuals and small businesses in the State of Nevada. The information collected during the application process, enrollment, customer support, and renewals will only be used to ensure the efficient operation of the Nevada Health Link, verify the eligibility of an individual to enroll through Nevada Health Link or to claim a premium tax credit or cost-sharing reduction, and the amount of the credit or reduction. This information will not be shared with any other person or entity unless it is required to determine eligibility or enroll in a QHP/SADP.
In order to facilitate enrollment in Nevada Health Link, and to determine eligibility for QHPs/SADPs, APTC, and CSR, Nevada Health Link must collect information necessary to authenticate identity, citizenship status, residency, income, and incarceration status. This data includes, but is not limited to:
- Demographic Data:Name, Address, Phone Number, Email, Age
- Income Data:Tax Filing Status, Marriage Status, Tax Dependents, Employer, Annual or Monthly Income
- Citizenship Data:Social Security Number, Resident Alien Number, Native American Tribe ID Number, Incarceration Status
- Disability Information:Whether the applicant/household member is blind, disabled, or requires assistance with daily living (this information cannot be used to deny coverage, but may help an individual to become eligible for Medicaid)
- Payment Information:Credit Card Numbers, Checking Account Numbers
- Health Insurance Coverage Information:Past and current health insurance coverage, tobacco use, consumer plan selections, and other information necessary to facilitate enrollment.
This information is captured during the application and enrollment process and is used during annual open enrollments to provide an expedited enrollment experience. To improve the Nevada Health Link portal and the overall usability of the site, some data regarding page views, browsing behavior, and system response times may also be collected. All personal data changes, eligibility results, plan selections, and any other action performed by the user will be tracked for audit and appeals purposes.
Each interaction between an individual and the Nevada Health Link website or call center will also be documented along with any communications, notifications, or emails. The primary purpose of recording this information is to help improve the efficiency of Nevada Health Link’s operations, including streamlined support of the appeals process.
Authority to Collect
45 CFR § 155.260 states that Nevada Health Link may collect PII to determine eligibility for enrollment in qualified health plans, to assess potential eligibility for Medicaid/CHIP, and to determine eligibility for exemptions from the individual mandate to maintain health insurance coverage. Nevada Health Link will fully comply with this federal regulation. Nevada Health Link will not create, collect, use or disclose personally identifiable information for any purposes that are not authorized under this regulation.
The following principles are outlined in the regulation:
- Individual Access: Individuals will be provided with a simple and timely means to access and obtain their personally identifiable health information
- Correction: Individuals will be provided with a timely means to dispute the accuracy of their personally identifiable health information and to have erroneous information corrected
- Openness and transparency: All policies, procedures, and technologies that affect individuals and their personally identifiable information are fully disclosed to the public
- Individual choice: Individuals will be provided a reasonable opportunity and capability to make informed decisions about the collection, use, and disclosure of their personally identifiable health information
- Collection, use, and disclosure limitations: Personally identifiable health information will be created, collected, used, and/or disclosed only to the extent necessary to accomplish the goals of Nevada Health Link
- Data quality and integrity: Persons and entities will take reasonable steps to ensure that personally identifiable health information is complete, accurate, and up- to-date to the extent necessary to provide services to the members of Nevada Health Link
- Safeguards: Personally identifiable health information is protected with reasonable operational, administrative, technical, and physical safeguards to ensure its confidentiality, integrity, and availability and to prevent unauthorized access, use, or disclosure
- Accountability: These principles are implemented, and adherence assured, through independent security audits by a third party.
Information Sharing with External Entities
Nevada Health Link will share information with insurance carriers, Nevada state agencies, and federal agencies, as required to process requests for enrollment in QHPs/SADPs and to determine eligibility for health/dental coverage, APTC, and CSR. The following table outlines the entities Nevada Health Link will share data with, and how that data is used. All entities that receive data from Nevada Health Link are required to support the same level of data security standards as Nevada Health Link itself.
# | Entity | Data | Usage of Data |
1 | Qualified Health and Dental Plan Carriers | Individual APTC Amount, Premium Amount, Plan Selection, Enrollment Status | Carriers are notified of the customer’s plan selection and account maintenance activities. Nevada Health Link is notified by Carriers of the enrollment status. |
2 | Nevada Division of Welfare and Supportive Services (DWSS) | Individual Demographic, Income, Citizenship, Disability | DWSS determines eligibility for Medicaid/CHIP in Nevada. Nevada Health Link will refer applications for coverage to DWSS via electronic data transfer if potential eligibility for Medicaid/CHIP is assessed. |
3 | Nevada Division of Health Care Financing and Policy (DHCFP) | Aggregated premium disbursement and premium collection amounts | As the administrator of Medicaid/CHIP in Nevada, DHCFP is required to account for the state and federal funds disbursed through the program. |
4 | U.S. Department of Health and Human Services, Centers for Medicare and Medicaid Services (CMS) | Individual Enrollment, premium, APTC | Nevada Health Link is federally mandated to report enrollment, premium, and APTC amounts to CMS for each enrolled individual. |
5 | U.S. Internal Revenue Service (IRS) | Individual Enrollment, premium, APTC | Nevada Health Link is federally mandated to report enrollment, premium, and APTC amounts to the IRS for each Tax Household. |
Information Sharing with Enrollment Professionals
Consumers may, at their own discretion, elect to share their information with enrollment professionals when requesting assistance with the application and enrollment process. Enrollment professionals include Navigators, whose role was created under the ACA to provide impartial education to consumers regarding ACA health/dental plans and subsidies, and who are not permitted to recommend specific plans; and private insurance agents/brokers, who are certified by Nevada Health Link to provide ACA education and enrollment assistance, and who may offer plan recommendations based on a consumer’s specific requirements. All enrollment professionals are required to comply with the terms of this policy, as well as with the terms of the Nevada Health Link Acceptable Use Agreement.
Before information will be shared with an enrollment professional a consumer must explicitly designate a Navigator or agent/broker using the Nevada Health Link website, or by calling the Nevada Health Link call center. Consumers may change or terminate their designation at any time.
Individual Access/Correction of Information
Individuals may access all of their PII collected by Nevada Health Link at any time through the user portal. Consumers are encouraged to review their application information on a regular basis to ensure its continued accuracy. Incorrect information can be corrected directly through the user portal, or by contacting the Nevada Health Link call center. Designated enrollment professionals can also correct information on behalf of their consumers.
Please note that per ACA regulations corrections to information provided on an application for coverage may result in a redetermination of eligibility.
Complaints Regarding the Improper Handling of PII
Complaints regarding the improper handling of PII should be submitted by email to the SSHIX Privacy Officer at privacy@exchange.nv.gov. All complaints will be reviewed by the Privacy Officer and the SSHIX Executive Director, and all appropriate or required action will be taken.
If the Executive Director believes that a complaint warrants a revision to the Nevada Health Link Privacy Policy then the change will be drafted by the SSHIX Change Control Board and submitted to the SSHIX Board of Directors for approval.
Operational, Technical, Administrative and Physical Safeguards
Consistent with all applicable laws and regulations, Nevada Health Link will ensure that all information is protected through effective administrative and operational procedures maintained by Nevada Health Link. Nevada Health Link will ensure the confidentiality, integrity, and availability of all personally identifiable information that is created, collected, used, or disclosed by Nevada Health Link.
Personally identifiable information will be used by, or disclosed to, only those authorized to receive or view it. ACA section 1411 states that “an applicant for insurance coverage or for a premium tax credit or cost-sharing reduction shall be required to provide only the information strictly necessary to authenticate identity, determine eligibility, and determine the amount of the credit or reduction.” It also states that this information must be used only for Nevada Health Link operations (such as verification of eligibility for enrollment, APTC, or CSR). Penalties of up to $25,000 per violation exist for anyone who knowingly and willfully violates this restriction.
Tax return information will be kept confidential in accordance with section 6103 of the Internal Revenue Code. The IRS will disclose certain available items of federal tax return information to the Data Services Hub after an individual submits an application for financial assistance in obtaining health coverage with Nevada Health Link or state agencies that administer Medicaid, CHIP, or basic health plans. The items that will be disclosed through the Data Services Hub are described under Internal Revenue Code section 6103(l)(21)(A) and the regulations issued under that section. Internal Revenue Code section 6103 protects the confidentiality of federal tax return information.
Disclosure of federal tax return information to the U.S. Department of Health and Human Services is allowed in order to implement eligibility determinations for health insurance affordability programs, within the confidentiality requirements in Internal Revenue Code section 6103.4
Personally identifiable information will be protected against any reasonably anticipated threats or hazards to the confidentiality, integrity, and availability of such information.
Personally identifiable information will be protected against any reasonably anticipated uses or disclosures that are not permitted or required by law.
Personally identifiable information will be securely destroyed or disposed of in an appropriate and reasonable manner and in accordance with retention schedules.
Security Controls
- Nevada Health Link will ensure that its workforce complies with all information safeguards and security controls.
- Nevada Health Link will monitor, periodically assess, and update security controls to ensure the continued effectiveness of those controls.
- Nevada Health Link will require, as a condition of contracts and agreements, the same or more stringent privacy and security standards and controls to Navigators, agents, brokers or other contractors authorized to access any personally identifiable information.
- Nevada Health Link will use secure electronic interfaces when sharing personally identifiable information electronically. ACA section 1413 requires the establishment of secure electronic interfaces with state health subsidy programs allowing the Nevada Health Link to be consistent with privacy and security standards in section 1942 of the Social Security Act.
- Nevada Health Link will ensure that all data matching and data sharing arrangements between Nevada Health Link and agencies administering the Medicaid and Children’s Health Insurance Program meet all requirements applicable to Nevada Health Link as well as all requirements applicable under Medicaid and the Children’s Health Insurance Program.
Nevada Privacy and Information Security Policies and Standards
Nevada Health Link follows standards, policies, and procedures designed to protect personal health information (PHI), personally identifiable information (PII), financial information and plan information entrusted to Nevada Health Link. Nevada Health Link’s portal and supporting systems adhere to federal security mandates and standards, specifically:
- Health Insurance Portability and Accountability Act (HIPAA) Security and Privacy Rules
- National Institute of Standards and Technology (NIST) guidelines, industry practices for security, confidentiality and auditing
- Nevada State-specific security requirements to secure data and information, including but not limited to NRS, 205.4742 and chapter 603A.